CyberRota Analysis
AI-GeneratedMattermost versions 11.8.x up to 11.8.2, 11.7.x up to 11.7.6, and 10.11.x up to 10.11.21 have a vulnerability that allows channel administrators to improperly assign elevated permissions through the channel member roles API. This could lead to unauthorized access and manipulation of channel settings, potentially compromising the integrity of channel data. Organizations using these versions should prioritize patching to mitigate the risk of privilege escalation.
Original NVD Description
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697
Related CVEs
Other vulnerabilities affecting the same vendor(s)